home *** CD-ROM | disk | FTP | other *** search
-
- *********************************************
- *** Reports collected and collated by ***
- *** PC-Virus Index ***
- *** with full acknowledgements ***
- *** to the authors ***
- *********************************************
-
- Vesselin Bontchev reported in May 1990:
-
- The Dark Avenger virus.
- ======================
-
- - I found two new mutations of this virus. Well, maybe "mutations"
- is not the correct word. In the first of them, the first 16
- characters of the string "Eddie lives... somewhere in time!" were
- replaced with blanks.
-
- In the second example, all strings (the message above, the copyright
- message and the "Diana P." string) were replaced with blanks. -
- The author of the Dark Avenger virus (The bastard! I still cannot
- determine who he is.) has released the source code of his virus.
-
- It is full with ironic comments about me. Of course, now we have to
- expect lots of new, similar viruses to appear. At least, this
- leaded to one good thing - the source helped me very much in
- disassembling the V2000 virus. - I received a rather offensive
- anonymous letter from this person. In it he claims to be also the
- author of both the V2000 (I trust this) and the Number of the Beast
- viruses (the latter is unlikely).
-
-
- === Computer Virus Catalog 1.2: "Dark Avenger" Virus (15-Feb-1990) ===
- Entry...............: Dark Avenger
- Alias(es)...........: ---
- Virus Strain........: Dark Avenger
- Virus detected when.: November 1989
- where.: USA
- Classification......: February 1990
- Length of Virus.....: about 1800 Bytes
- -------------------- Preconditions -----------------------------------
- Operating System(s).: DOS
- Version/Release.....:
- Computer model(s)...: IBM-compatible
- -------------------- Attributes --------------------------------------
- Easy Identification.: Two Texts:
- "Eddie lives...somewhere in time" at beginning
- and
- "This Program was written in the City of Sofia
- (C) 1988-89 Dark Avenger" near end of file
-
- Type of infection...: Link-virus
- COM-files: appends to the program and installs a
- short jump
- EXE-files: appends to the program at the
- beginning of the next paragraph
-
- Infection Trigger...: COM and EXE files are corrupted on any read
- attempt even when VIEWING!!!
-
- Storage media affected: Any Drive
-
- Interrupts hooked...: Int 21 DOS-services
- Int 27 Terminate and Stay Resident
-
- Damage..............: Overwrites a random sector with bootblock
-
- Damage Trigger......: each 16th infection; counter located in
- Bootblock
-
- Particularities.....: -
-
- Similarities........: -
-
- -------------------- Agents ------------------------------------------
-
- Countermeasures.....: NONE! All data can be destroyed !!!!
- There is no way in retrieving lost data.
- Backups will most probably be destroyed too.
-
- Countermeasures successful: install McAfee's SCANRES.
-
- Standard means......: Good luck! Hopefully the virus did not destroy
- too many of your programs and data.
-
- -------------------- Acknowledgement ---------------------------------
-
- Location............: VTC Uni Hamburg
- Classification by...: Matthias Jaenichen
- Documentation by....: Matthias Jaenichen
- Date................: 31.01.1990
- Information Source..: ---
-
-
- ===================== End of "Dark Avenger" Virus ====================
-
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
- ++++++++++++++++++++++++++ end of reports ++++++++++++++++++++++++
- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++